Skip to content

build(deps): bump the python-minor-and-patch group across 1 directory with 19 updates - #64

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-and-patch-b96edac038
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-and-patch-b96edac038

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown

Bumps the python-minor-and-patch group with 19 updates in the / directory:

Package From To
boto3 1.43.38 1.43.108
certifi 2026.6.17 2026.7.22
cryptography 50.0.1 50.0.2
litellm 1.96.0 1.103.2
packaging 26.2 26.3
pydantic 2.12.5 2.13.5
pymongo 4.17.0 4.18.2
starlette 1.3.1 1.7.0
uvicorn 0.49.0 0.54.0
e2b 2.46.4 2.52.0
fastapi 0.141.1 0.142.2
google-api-core 2.31.0 2.40.0
google-auth 2.55.1 2.59.1
google-cloud-secret-manager 2.30.0 2.31.0
google-cloud-storage 3.15.0 3.16.0
moto 5.2.2 5.2.3
psycopg2-binary 2.9.12 2.9.13
pytest-socket 0.8.0 0.8.1
regex 2026.6.28 2026.9.29

Updates boto3 from 1.43.38 to 1.43.108

Commits

Updates certifi from 2026.6.17 to 2026.7.22

Commits

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates litellm from 1.96.0 to 1.103.2

Release notes

Sourced from litellm's releases.

v1.103.2

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.2/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.2

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

Full Changelog: BerriAI/litellm@v1.103.1...v1.103.2

v1.103.1

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

... (truncated)

Commits
  • f69b210 Merge pull request #43984 from BerriAI/litellm_backport_lit9020_stable_1_103_x
  • 2869a6f fix(proxy): restore pre-config-wins handling of pass-through endpoints (#43962)
  • afbda35 Merge pull request #43662 from BerriAI/litellm_backport_safeguards_stable_1_1...
  • f146256 Merge pull request #43897 from BerriAI/litellm_backport_usage_attribution_sta...
  • fe87252 chore(release): bump litellm-enterprise 0.1.69 -> 0.1.69.post1 for stable/1.1...
  • 1bbc9ee test(integration): register the daily activity key metadata contracts on stab...
  • 460d51f bump: version 1.103.2
  • 97f670a fix(proxy): look up hashed key names with two spend log rows per key (#43656)
  • 00b8664 fix(proxy): recover session key owners from daily spend for usage attribution...
  • 74952e9 test(integration): add the scratch_database harness helper
  • Additional commits viewable in compare view

Updates packaging from 26.2 to 26.3

Release notes

Sourced from packaging's releases.

26.3

What's Changed

Features

  • Add a public VersionRange API and SpecifierSet.to_range(), representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. VersionRange.to_specifier_set() converts a range back to a SpecifierSet where a PEP 440 form exists. (#1267, #1270, #1298)
  • PEP 808: accept Metadata-Version: 2.6. (#1194)
  • Add a limit argument to parse_tag() for compressed tag sets. (#1220)
  • Add a prefer_sdist_predicate argument to Pylock.select() to prefer source distributions over wheels for selected packages. (#1334)
  • Add pure_python_tags() to generate the pure-Python tags for a Python version without touching the running platform. (#1346)
  • Add SpecifierSet.is_subset(), SpecifierSet.is_superset(), and SpecifierSet.is_disjoint(), which compare the versions two specifier sets accept. (#1313)

Behavior adaptations

  • Drop support for Python 3.8; packaging now requires Python 3.9 or later. (#1157)
  • Prefer native linux_* platform tags over manylinux and musllinux tags on Linux. (#160)

Fixes for versions and specifiers

  • Raise InvalidVersion instead of TypeError when Version is given a non-string. (#1319)
  • Raise InvalidVersion for non-string pre-release letters passed to Version.from_parts. (#1241)
  • Fix an AttributeError when hashing internally trimmed versions. (#1242)
  • Fix SpecifierSet.is_unsatisfiable for post-release boundary intersections. (#1257)

Fixes for requirements and markers

  • Make Requirement.__hash__ consistent with __eq__ for trailing-zero-equivalent specifiers (e.g. foo==1.0.0 and foo==1.0.0.0), so equal requirements hash equal and deduplicate in sets and dicts. (#1232)
  • Normalize requested extra names before comparing or hashing requirements. (#644)
  • Preserve a Requirement's specifier prereleases override across a pickle round trip. (#1204)
  • Raise InvalidRequirement instead of InvalidSpecifier when a requirement contains an invalid specifier. (#1332)
  • Clarify the error for post-release prefix wildcards like ==1.0.post1.*. (#1299)
  • Preserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (#1213)
  • Keep the parentheses of a nested group when serializing markers. (#1316)
  • Normalize extra and dependency_groups values in nested markers at parse time. (#1246, #1310)
  • Raise UndefinedComparison when a set-valued variable like extras is used outside the membership form. (#1265)
  • Raise UndefinedEnvironmentName (a KeyError subclass) for missing environment keys during marker evaluation. (#1276)
  • Wrap malformed string literal errors in InvalidMarker / InvalidRequirement instead of leaking a low-level error. (#1249)
  • Reject requirements and markers with a trailing line break. (#1345)

Fixes for metadata and licenses

  • Collect all from_email validation errors into one ExceptionGroup instead of raising the first. (#1268)
  • Accept the UTF-8 charset case-insensitively in email payloads. (#1330)
  • Reject malformed Description-Content-Type values. (#1329)
  • Don't rewrite user values that contain {field} placeholders in error messages. (#1327)
  • Route multipart email payloads to unparsed instead of asserting. (#1247)
  • Make InvalidMetadata and CyclicDependencyGroup picklable. (#1328)
  • Fold every line boundary str.splitlines recognizes when writing a header with RFC822Message. (#1356)

... (truncated)

Changelog

Sourced from packaging's changelog.

26.3 - 2026-08-03


Features:
  • Add a public :class:~packaging.ranges.VersionRange API and
    :meth:SpecifierSet.to_range() <packaging.specifiers.SpecifierSet.to_range>,
    representing the versions a specifier set accepts as an interval set that
    supports intersection, union, difference, complement, set relations,
    membership tests, and filtering.
    :meth:~packaging.ranges.VersionRange.to_specifier_set converts a range back
    to a :class:~packaging.specifiers.SpecifierSet where a PEP 440 form exists.
    (:pull:1267, :pull:1270, :pull:1298)
  • PEP 808: accept Metadata-Version: 2.6. (:pull:1194)
  • Add a limit argument to parse_tag() for compressed tag sets.
    (:issue:1220)
  • Add a prefer_sdist_predicate argument to Pylock.select() to prefer
    source distributions over wheels for selected packages. (:pull:1334)
  • Add :func:~packaging.tags.pure_python_tags to generate the pure-Python
    tags for a Python version without touching the running platform.
    (:pull:1346)
  • Add :meth:SpecifierSet.is_subset() <packaging.specifiers.SpecifierSet.is_subset>, :meth:~packaging.specifiers.SpecifierSet.is_superset,
    and :meth:~packaging.specifiers.SpecifierSet.is_disjoint, which compare the
    versions two specifier sets accept. (:pull:1313)

Behavior adaptations:

  • Drop support for Python 3.8; packaging now requires Python 3.9 or later.
    (:pull:1157)
  • Prefer native linux_* platform tags over manylinux and musllinux
    tags on Linux. (:issue:160)

Fixes for versions and specifiers:

  • Raise InvalidVersion instead of TypeError when Version is given a
    non-string. (:pull:1319)
  • Raise InvalidVersion for non-string pre-release letters passed to
    Version.from_parts. (:pull:1241)
  • Fix an AttributeError when hashing internally trimmed versions.
    (:pull:1242)
  • Fix SpecifierSet.is_unsatisfiable for post-release boundary
    intersections. (:pull:1257)

Fixes for requirements and markers:

  • Make Requirement.__hash__ consistent with __eq__ for
    trailing-zero-equivalent specifiers (e.g. foo==1.0.0 and
    foo==1.0.0.0), so equal requirements hash equal and deduplicate in
    sets and dicts. (:pull:1232)
    </tr></table>

... (truncated)

Commits
  • 929fd4b Bump for release
  • f300ebf chore(deps): bump the pre-commit group with 5 updates (#1357)
  • f91d975 ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (#1361)
  • b1a7124 chore(deps): bump the github-actions group with 7 updates (#1358)
  • 2d873eb fix(metadata): fold every line boundary when writing headers (#1356)
  • 413d006 docs: changelog for 26.3 (#1343)
  • 4eb0753 docs(metadata): explain selective field validation (#1342)
  • 77e9ed4 feat(tags): add pure Python tag generator (#1346)
  • 7cea5e8 ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...
  • 45a8b34 docs: add missing versionadded/versionchanged directives (#1344)
  • Additional commits viewable in compare view

Updates pydantic from 2.12.5 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 2026-05-06

v2.13.4 (2026-05-06)

What's Changed

Packaging

Fixes

Full Changelog: pydantic/pydantic@v2.13.3...v2.13.4

v2.13.3 2026-04-20

v2.13.3 (2026-04-20)

What's Changed

Fixes

Full Changelog: pydantic/pydantic@v2.13.2...v2.13.3

v2.13.2 2026-04-17

v2.13.2 (2026-04-17)

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

Full Changelog: pydantic/pydantic@v2.13.1...v2.13.2

v2.13.1 2026-04-15

... (truncated)

Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates pymongo from 4.17.0 to 4.18.2

Release notes

Sourced from pymongo's releases.

PyMongo 4.18.2

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732

CVE-2026-96749 CVE-2026-96748 CVE-2026-96747

PyMongo 4.18.1

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-1-released/343338

PyMongo 4.18.0

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-released/343137

Changelog

Sourced from pymongo's changelog.

Changes in Version 4.18.2 (2026/09/24)

Version 4.18.2 is a bug fix release.

  • Hardened the bson buffer size guard against signed integer overflow. (CVE-2026-96749_).
  • Fixed connection string parsing to percent-decode each host individually. (CVE-2026-96748_).
  • Client-side field level encryption now rejects a KMS endpoint ending in .sock. (CVE-2026-96747_).

.. _CVE-2026-96749: https://www.cve.org/CVERecord?id=CVE-2026-96749 .. _CVE-2026-96748: https://www.cve.org/CVERecord?id=CVE-2026-96748 .. _CVE-2026-96747: https://www.cve.org/CVERecord?id=CVE-2026-96747

Issues Resolved ...............

See the PyMongo 4.18.2 release notes in JIRA_ for the list of resolved issues in this release.

.. _PyMongo 4.18.2 release notes in JIRA: https://jira.mongodb.org/secure/ReleaseNote.jspa?projectId=10004&version=52896

Changes in Version 4.18.1 (2026/09/10)

Version 4.18.1 is a bug fix release.

  • Use an exact match for the file ID in GridFS delete methods (CVE-2026-88029_).

.. _CVE-2026-88029: https://www.cve.org/CVERecord?id=CVE-2026-88029

Changes in Version 4.18.0 (2026/09/03)

PyMongo 4.18 brings a number of changes including:

  • Added srvAllowedHostsSuffix as a URI option and keyword argument to :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient. When connecting via mongodb+srv://, this option overrides the default requirement that SRV-returned hosts share the same parent domain as the seed hostname, allowing hosts under a different domain suffix to be accepted. The suffix must not be a public suffix (per the Public Suffix List <https://publicsuffix.org/list/>_). See the :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient documentation for security considerations.
  • Dropped support for MongoDB 4.2.
  • Added support for MongoDB 9.0.
  • PyPy support is deprecated and will be removed in a future release.

... (truncated)

Commits

Updates starlette from 1.3.1 to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Version 1.6.0

What's Changed

New Contributors

Full Changelog: Kludex/starlette@1.5.1...1.6.0

... (truncated)

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

1.6.0 (August 8, 2026)

Added

  • Add max_body_size to Starlette and route classes #3431.
  • Expose http.response.debug information via response extensions #3130.

1.5.1 (August 8, 2026)

... (truncated)

Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates uvicorn from 0.49.0 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Version 0.52.3

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)

... (truncated)

Commits
  • 3eb9a9a Version 0.54.0 (#3161)
  • cd7ef6d Remove races from supervisor tests (#3134)
  • a56c7cc Support HTTP/2 response trailers (#3146)
  • 9bd4404 chore(deps): bump anyio from 4.13.0 to 4.14.2 (#3145)
  • 21f39ef Add HTTP/2 Early Hints support (#3137)
  • 421708f Version 0.53.0 (RetriggerConfidence Score: 4/5

    The PR is not ready to merge until the Uvicorn minimum again covers the local grant server’s TLS setting.

    Fix All in CursorFindings

    1. P1 Local object grants fail ▶
    2. P2 Shipped notices name old versions ▶
    Fix with agent prompt
    ### Issue 1
    pyproject.toml:47
    If an install uses `uvicorn` 0.29–0.46, the local grant server passes `ssl_context_factory` to `uvicorn.Config`, which only accepts it from 0.47 onward. The first request for an object grant then raises `TypeError`, so object transfers that need the grant fail. Keep the minimum at 0.47.
    
    ```suggestion
        "uvicorn>=0.47",  # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
    ```
    
    ### Issue 2
    uv.lock:2315
    `uv.lock` now selects `pymongo` 4.18.2, but the shipped `THIRD_PARTY_NOTICES.md` still lists 4.17.0. It also lists the old `litellm` release. Update the notices with the lockfile so package recipients can tell which dependency versions they received.
    
    Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
    
    ---
    
    For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

    Summary

    The PR refreshes the Python dependency versions in pyproject.toml and uv.lock. It also widens or adjusts the allowed version ranges for LiteLLM, E2B, and Uvicorn.

    • The project now allows updated Python packages and locks their selected versions.

    Reviews (1) · Last reviewed commit: "build(deps): bump the python-minor-and-p..."

… with 19 updates

Bumps the python-minor-and-patch group with 19 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.38` | `1.43.108` |
| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [litellm](https://github.com/BerriAI/litellm) | `1.96.0` | `1.103.2` |
| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |
| [pymongo](https://github.com/mongodb/mongo-python-driver) | `4.17.0` | `4.18.2` |
| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.7.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.54.0` |
| [e2b](https://github.com/e2b-dev/e2b) | `2.46.4` | `2.52.0` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.2` |
| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.31.0` | `2.40.0` |
| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.1` | `2.59.1` |
| [google-cloud-secret-manager](https://github.com/googleapis/google-cloud-python) | `2.30.0` | `2.31.0` |
| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.15.0` | `3.16.0` |
| [moto](https://github.com/getmoto/moto) | `5.2.2` | `5.2.3` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` |
| [pytest-socket](https://github.com/miketheman/pytest-socket) | `0.8.0` | `0.8.1` |
| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.6.28` | `2026.9.29` |



Updates `boto3` from 1.43.38 to 1.43.108
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.38...1.43.108)

Updates `certifi` from 2026.6.17 to 2026.7.22
- [Commits](certifi/python-certifi@2026.06.17...2026.07.22)

Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `litellm` from 1.96.0 to 1.103.2
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.96.0...v1.103.2)

Updates `packaging` from 26.2 to 26.3
- [Release notes](https://github.com/pypa/packaging/releases)
- [Changelog](https://github.com/pypa/packaging/blob/main/CHANGELOG.rst)
- [Commits](pypa/packaging@26.2...26.3)

Updates `pydantic` from 2.12.5 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.12.5...v2.13.5)

Updates `pymongo` from 4.17.0 to 4.18.2
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.17.0...4.18.2)

Updates `starlette` from 1.3.1 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.3.1...1.7.0)

Updates `uvicorn` from 0.49.0 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.49.0...0.54.0)

Updates `e2b` from 2.46.4 to 2.52.0
- [Release notes](https://github.com/e2b-dev/e2b/releases)
- [Commits](https://github.com/e2b-dev/e2b/compare/@e2b/python-sdk@2.46.4...e2b@2.52.0)

Updates `fastapi` from 0.141.1 to 0.142.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.141.1...0.142.2)

Updates `google-api-core` from 2.31.0 to 2.40.0
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-api-core-v2.31.0...google-api-core-v2.40.0)

Updates `google-auth` from 2.55.1 to 2.59.1
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-auth-v2.55.1...google-auth-v2.59.1)

Updates `google-cloud-secret-manager` from 2.30.0 to 2.31.0
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-cloud-secret-manager-v2.30.0...google-cloud-secret-manager-v2.31.0)

Updates `google-cloud-storage` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/googleapis/google-cloud-python/releases)
- [Changelog](https://github.com/googleapis/google-cloud-python/blob/main/packages/google-cloud-documentai/CHANGELOG.md)
- [Commits](googleapis/google-cloud-python@google-cloud-storage-v3.15.0...google-cloud-storage-v3.16.0)

Updates `moto` from 5.2.2 to 5.2.3
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](getmoto/moto@5.2.2...5.2.3)

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](psycopg/psycopg2@2.9.12...2.9.13)

Updates `pytest-socket` from 0.8.0 to 0.8.1
- [Release notes](https://github.com/miketheman/pytest-socket/releases)
- [Changelog](https://github.com/miketheman/pytest-socket/blob/main/CHANGELOG.md)
- [Commits](miketheman/pytest-socket@0.8.0...0.8.1)

Updates `regex` from 2026.6.28 to 2026.9.29
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.6.28...2026.9.29)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.108
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: certifi
  dependency-version: 2026.7.22
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: litellm
  dependency-version: 1.103.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: packaging
  dependency-version: '26.3'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: pymongo
  dependency-version: 4.18.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: e2b
  dependency-version: 2.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: fastapi
  dependency-version: 0.142.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-api-core
  dependency-version: 2.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-auth
  dependency-version: 2.59.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-cloud-secret-manager
  dependency-version: 2.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: google-cloud-storage
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: moto
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: pytest-socket
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: regex
  dependency-version: 2026.9.29
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 6, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 16:31
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 6, 2026
Comment thread pyproject.toml
"pyyaml>=6.0",
"starlette>=0.40", # the local grant server
"uvicorn>=0.47", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
"uvicorn>=0.29", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Local object grants fail

If an install uses uvicorn 0.29–0.46, the local grant server passes ssl_context_factory to uvicorn.Config, which only accepts it from 0.47 onward. The first request for an object grant then raises TypeError, so object transfers that need the grant fail. Keep the minimum at 0.47.

Suggested change
"uvicorn>=0.29", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
"uvicorn>=0.47", # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
Prompt To Fix With AI
This is a comment left during a code review.
Path: pyproject.toml
Line: 47

Comment:
**Local object grants fail**

If an install uses `uvicorn` 0.29–0.46, the local grant server passes `ssl_context_factory` to `uvicorn.Config`, which only accepts it from 0.47 onward. The first request for an object grant then raises `TypeError`, so object transfers that need the grant fail. Keep the minimum at 0.47.

```suggestion
    "uvicorn>=0.47",  # 0.47 adds ssl_context_factory, how the local grant server gets its TLS context
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Fix in Cursor Fix in Claude Code Fix in Codex

Comment thread uv.lock
@@ -2296,63 +2312,63 @@ crypto = [

[[package]]
name = "pymongo"
version = "4.17.0"
version = "4.18.2"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Shipped notices name old versions

uv.lock now selects pymongo 4.18.2, but the shipped THIRD_PARTY_NOTICES.md still lists 4.17.0. It also lists the old litellm release. Update the notices with the lockfile so package recipients can tell which dependency versions they received.

Prompt To Fix With AI
This is a comment left during a code review.
Path: uv.lock
Line: 2315

Comment:
**Shipped notices name old versions**

`uv.lock` now selects `pymongo` 4.18.2, but the shipped `THIRD_PARTY_NOTICES.md` still lists 4.17.0. It also lists the old `litellm` release. Update the notices with the lockfile so package recipients can tell which dependency versions they received.

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Cursor Fix in Claude Code Fix in Codex

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants